Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

JFrog has reached a major milestone: An IRAP assessment at the Protected level, across the full JFrog Platform. Conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed assessor, against the ISM, it independently validates that the platform managing an agency’s software supply chain meets the bar for Australia’s most sensitive workloads. It reasserts a commitment that …

SLSA - Thumbnail

The Secret Sauce of SLSA: DevGovOps at the Speed of Agentic AI

Software supply chain engineering has reached a critical inflection point. As autonomous AI coding agents transition from generating autocomplete suggestions to planning, writing, reviewing, and deploying entire software pipelines without humans in the loop, the connection between human intent and production binaries is fracturing. This shift has created a severe structural deficit across enterprise tech …

DevGovOps - Thumbnail

Governance at the Speed of AI: How DevGovOps Closes the DORA Compliance Gap

What is DevGovOps? DevGovOps is a Software Supply Chain Engineering practice that integrates continuous governance and compliance into the DevOps software delivery lifecycle. Rather than treating compliance as a retrospective, manual hurdle, DevGovOps ensures that policy enforcement, continuous auditability, and cryptographic traceability are natural outputs of every release. By shifting from point-in-time checks to continuous …

Why Uniform Governance Fails with Enterprise AI Agents (And How to Fix It)

As organizations aggressively shift from static Large Language Model (LLM) chatbots to fully dynamic, autonomous AI agents (e.g. systems designed to plan workflows, call APIs, write runtime code, and modify enterprise databases), traditional compliance and governance frameworks are hitting a breaking point. A landmark press release from Gartner highlights a critical systemic risk: treating AI …

NVIDIA NIM Models Are Now Governed Assets in Your Supply Chain

NVIDIA NIM (NVIDIA Inference Microservices) packages production-ready AI models into optimized containers for enterprise deployment. Your developers need them. Your coding agents pull them. And until now, they pulled them directly from NVIDIA’s NGC registry, bypassing the supply chain controls you’ve spent years building. JFrog AI Catalog now brings NVIDIA NIM models under the same …

The Governance Gap Between Your Policy and Your Pipeline

Security teams are under more pressure than ever, and most of them believe they’re keeping up. That confidence, it turns out, may be the most consequential finding in the JFrog 2026 Software Supply Chain Security State of the Union. Across 18.2 billion artifacts analyzed, independent vulnerability research from the JFrog Security Research team, and a …